Title 22Foreign Relations and IntercourseRelease 119-73

§2684b Strengthening the Chief Information Officer of the Department of State

Title 22 › Chapter CHAPTER 38— - DEPARTMENT OF STATE › § 2684b

Last updated Apr 6, 2026|Official source

Summary

The Department's Chief Information Officer (CIO) must be consulted before approving or rejecting any major new unclassified IT spending, including software. The CIO's input is meant to promote department-wide software and tech that can be shared, boost the Department’s buying power, cut duplicate security approvals, make systems work better together, improve training and staff skills, lower costs by retiring old systems, keep security rules consistent, and strengthen user training and cybersecurity. Within 180 days after December 22, 2023, the CIO must create a strategy and a 5-year plan, and also set policies to improve customer service and support for bureau IT officers. The CIO must submit the strategy to the appropriate congressional committees by one year after December 22, 2023 and consult with them yearly for five years. The CIO must run a client satisfaction survey no later than one year after December 22, 2023 and then every year for five years, and send a summary of each survey within 60 days to the appropriate committees, the Senate Committee on Homeland Security and Governmental Affairs, and the House Committee on Oversight and Accountability. A "significant expenditure" means more than $250,000 total in one fiscal year for a new unclassified software or IT capability. This does not change the roles of OMB, the Office of the National Cyber Director, DHS, CISA, or existing CIO duties under titles 40 or 44 or other laws.

Full Legal Text

Title 22, §2684b

Foreign Relations and Intercourse — Source: USLM XML via OLRC

(a)The Chief Information Officer of the Department shall be consulted on all decisions to approve or disapprove, significant new unclassified information technology expenditures, including software, of the Department, including expenditures related to information technology acquired, managed, and maintained by other bureaus and offices within the Department, in order to—
(1)encourage the use of enterprise software and information technology solutions where such solutions exist or can be developed in a timeframe and manner consistent with maintaining and enhancing the continuity and improvement of Department operations;
(2)increase the bargaining power of the Department in acquiring information technology solutions across the Department;
(3)reduce the number of redundant Authorities to Operate (ATO), which, instead of using one ATO-approved platform across bureaus, requires multiple ATOs for software use cases across different bureaus;
(4)enhance the efficiency, reduce redundancy, and increase interoperability of the use of information technology across the enterprise of the Department;
(5)enhance training and alignment of information technology personnel with the skills required to maintain systems across the Department;
(6)reduce costs related to the maintenance of, or effectuate the retirement of, legacy systems;
(7)ensure the development and maintenance of security protocols regarding the use of information technology solutions and software across the Department; and
(8)improve end-user training on the operation of information technology solutions and to enhance end-user cybersecurity practices.
(b)(1)Not later than 180 days after December 22, 2023, the Chief Information Officer of the Department shall develop, in consultation with relevant bureaus and offices as appropriate, a strategy and a 5-year implementation plan to advance the objectives described in subsection (a).
(2)No later than one year after December 22, 2023, the Chief Information Officer shall submit the strategy required by this subsection to the appropriate congressional committees and shall consult with the appropriate congressional committees, not less than on an annual basis for 5 years, regarding the progress related to the implementation plan required by this subsection.
(c)(1)Not later than 180 days after December 22, 2023, the Chief Information Officer shall develop policies and protocols to improve the customer service orientation, quality and timely delivery of information technology solutions, and training and support for bureau and office-level information technology officers.
(2)Not later than one year after December 22, 2023, and annually thereafter for five years, the Chief Information Officer shall undertake a client satisfaction survey of bureau information technology officers to obtain feedback on metrics related to—
(A)customer service orientation of the Bureau of Information Resources Management; 1
(B)quality and timelines of capabilities delivered;
(C)maintenance and upkeep of information technology solutions;
(D)training and support for senior bureau and office-level information technology officers; and
(E)other matters which the Chief Information Officer, in consultation with client bureaus and offices, determines appropriate.
(3)Not later than 60 days after completing each survey required under paragraph (2), the Chief Information Officer shall submit a summary of the findings to the appropriate congressional committees, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Oversight and Accountability of the House of Representatives.
(d)For purposes of this section, the term “significant expenditure” means any cumulative expenditure in excess of $250,000 total in a single fiscal year for a new unclassified software or information technology capability.
(e)Nothing in this section may be construed—
(1)to alter the authorities of the United States Office of Management and Budget, Office of the National Cyber Director, the Department of Homeland Security, or the Cybersecurity and Infrastructure Security Agency with respect to Federal information systems; or
(2)to alter the responsibilities and authorities of the Chief Information Officer of the Department as described in titles 40 or 44 or any other law defining or assigning responsibilities or authorities to Federal Chief Information Officers.

Legislative History

Notes & Related Subsidiaries

Statutory Notes and Related Subsidiaries

Strengthening Enterprise Governance Pub. L. 119–60, div. E, title I, § 5174, Dec. 18, 2025, 139 Stat. 1588, provided that: “(a) Organization.—The Chief Information Officer and the Chief Data and Artificial Intelligence Officer of the Department should work collaboratively on strengthening enterprise governance of the Department [of State] and report directly to the Deputy Secretary [of State]. “(b) Adjudication of Unresolved Budget and Management Decisions.—Adjudication of unresolved budget and management decisions should be made by the Deputy Secretary. Definitions For definitions of “Department” and “appropriate congressional committees” as used in this section, see section 6002 of Pub. L. 118–31, set out as a note under section 2651 of this title.

Reference

Citations & Metadata

Citation

22 U.S.C. § 2684b

Title 22Foreign Relations and Intercourse

Last Updated

Apr 6, 2026

Release point: 119-73